tickets #168487
openasgard stops routing IPv6 randomly
0%
Description
In the last months we found twice that asgard1 would no longer forward IPv6 packets from/to the SUSE side gateway (= our path to the internet and to SUSE side hosts like the login proxies). Presumably only "new" sessions are affected as I would still be connected to the VPN with no issues at the time. Also internal routing (between openSUSE VLANs) would still work fine. No odd kernel messages or similar are found at the problematic time. Switching traffic over to asgard2 makes all traffic work again. I then use the opportunity to install updates on asgard1, reboot, and with that switch traffic back, and it continues to work.
This happening randomly without any noteworthy log entries makes it rather difficult to debug and reproduce. At the problematic time my focus is usually also to get connectivity back fast which does not leave much room for debugging.
However I did find the second time it happened that tcpdump on the os-p2p-pub interface (the one facing the gateway) filtering for ICMP from the login proxies (which I used to test-ping from the SUSE side) did not record any packets arriving.